Legal · Privacy

Privacy Policy

How Faden collects, uses, discloses and protects personal information — for the tailoring studios who use us, and for their customers.

Effective 14 July 2026

Faden is trusted with sensitive information — a person's measurements, contact details and buying history. We treat that seriously. This Policy sets out, in plain language, what we collect, why, who we share it with, and the choices you have.

01Who we are & scope

Faden ("Faden", "we", "us", "our") provides software that made-to-measure and bespoke tailoring businesses ("Studios") use to run their operations — clients, orders, fittings, production, messaging and payments. Faden is operated from Brisbane, Queensland, Australia.

This Privacy Policy explains how we handle personal information in connection with the Faden platform at faden.tech and its subdomains (the "Service"). It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and it also describes how we support the rights of individuals located overseas.

If you need our registered business details (legal entity name and ABN) for your records, contact us at privacy@faden.tech and we will provide them.

02Two kinds of data, two roles

The Service involves two distinct relationships, and our privacy obligations differ between them:

Account data — we are the controller

Information about the Studios that subscribe to Faden and the staff who use it (account, billing, settings, usage and support data). We decide how this information is handled and are responsible for it under this Policy.

Client data — we are a processor

The information a Studio stores about its own customers ("Client Data") — profiles, contact details, measurements, orders, communications and payment records. The Studio is the entity responsible for that data (the controller); Faden processes it strictly on the Studio's instructions to provide the Service. If you are a customer of a Studio, that Studio is your first point of contact for privacy requests, and its own privacy policy governs how it uses your information. We assist Studios in meeting their obligations (see Your rights).

03Information we collect

Account & identity

  • Studio and staff details: business name, contact name, email address, phone number, role, and the password hash or single sign-on identifier used to authenticate.
  • Business profile and settings: trading details, locations, tax registration (e.g. ABN/GST), branding and preferences you enter.

Billing

  • Subscription plan, add-ons, invoices and payment history. Card details are entered directly with our payment processor (Stripe) and tokenised — Faden never receives or stores full card numbers.

Client Data you enter (processed on your behalf)

  • Customer profiles: name, email, phone, addresses, notes and style notes.
  • Body measurements, fit information and garment specifications.
  • Orders, quotes, invoices, payments and refunds.
  • Communications with customers (email, SMS, WhatsApp and call records, where those features are used).

Technical & usage

  • Log and device data: IP address, browser type, pages accessed, timestamps and actions taken, used to operate the Service, keep it secure and diagnose faults.
  • A small number of strictly necessary cookies to keep you signed in and protect the Service (see Cookies).

04How we collect it

  • Directly from you when you sign up, configure your Studio, contact support or use the Service.
  • Automatically as you use the Service (log, device and usage data).
  • From a Studio, where you are that Studio's customer and the Studio has entered your information into the Service.
  • From integrations you choose to connect (for example, a payment gateway or accounting system), limited to what those services return.

Where it is reasonable and practicable, we collect personal information directly from the individual concerned. We collect only what we need for the purposes below.

05Why we use it

We use personal information to:

  • Provide, operate, secure and improve the Service.
  • Authenticate users and protect accounts (including multi-factor authentication, rate limiting and abuse detection).
  • Process subscriptions, take payment and issue tax invoices.
  • Provide support, send service and administrative messages, and respond to requests.
  • Meet legal, tax and accounting obligations.
  • With consent where required, send product updates about Faden. You can opt out of marketing at any time.

We do not sell personal information, and we do not use a Studio's Client Data for our own marketing.

06AI-assisted features

Faden offers an optional AI copilot that can draft client messages and summarise a client for a staff member. It is off by default and must be switched on by a Studio owner.

  • When enabled, only the minimum context needed for the task is sent to our AI sub-processor (Anthropic) — for example a customer's first name and last initial plus order details. We do not send surnames, email addresses, phone numbers or postal addresses.
  • AI-generated drafts are always shown to a staff member before anything is sent.
  • Neither we nor our AI sub-processor use your data or your customers' data to train, fine-tune or improve AI models.
  • Usage is metered and rate-limited; we log which staff member ran an action and token counts for billing and abuse-prevention, but never the prompt content or the generated text.

07Disclosure & sub-processors

We disclose personal information only as needed to run the Service, and we require our sub-processors to protect it. The core sub-processors we use are:

  • Hosting & database — our own infrastructure located in Australia, where your data is stored (encrypted at rest).
  • Stripe — payment processing for Faden subscriptions and, where a Studio connects it, for that Studio's own customer payments.
  • Twilio — SMS, WhatsApp and voice calls, where those features are used.
  • SendGrid — delivery of transactional and (where consented) marketing email.
  • Anthropic — the AI copilot, only when a Studio has enabled it (see AI-assisted features).
  • Xero — where a Studio connects it, one-way posting of that Studio's invoices, payments and refunds to its own Xero organisation.
  • Cloudflare — DNS and network protection for our domains.

We may also disclose information where required by law, to enforce our terms, to protect the rights or safety of any person, or as part of a business transfer (in which case this Policy continues to apply).

A Studio can see, in its own settings, exactly which sub-processors are active for its account, because several of the above only engage when the Studio turns on the corresponding feature.

08Overseas disclosure

Your data is stored on infrastructure located in Australia. However, some sub-processors listed above operate globally and may process limited data outside Australia (for example, in the United States) when you use the relevant feature.

Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the APPs, including through contractual protections. By using a feature that relies on an overseas sub-processor, you acknowledge this handling.

09How we protect it

We take security seriously and apply layered technical and organisational controls, including:

  • Encryption in transit (TLS) and encryption at rest, with sensitive fields — such as customer contact details, notes and body measurements — encrypted at the field level using AES-256-GCM.
  • Strict tenant isolation: each Studio's data is separated at the database level so one Studio can never read another's.
  • Blind-indexed lookups so we can match records without exposing the underlying personal information.
  • Authentication controls including hashed credentials, optional and enforceable multi-factor authentication, single sign-on, session management, IP allow-listing and rate limiting.
  • A tamper-evident audit log of sensitive actions, and least-privilege access for our own personnel.

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm, we will assess and respond in line with the Notifiable Data Breaches scheme under the Privacy Act, and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required. Where the breach concerns a Studio's Client Data, we will notify the Studio so it can meet its own obligations.

10Retention & deletion

We keep personal information only for as long as needed for the purposes above or as required by law.

  • Account data is retained while your subscription is active and for a reasonable period afterward, then deleted or de-identified.
  • Client Data is retained under the Studio's control. A Studio can export its data at any time and can request deletion. Studios also have built-in tools to export, erase and auto-anonymise individual customer records.
  • Some records (for example, transaction and tax records) must be retained for a legally required period; where we cannot delete them, we de-identify them instead of keeping them in full.
  • When a customer record is erased, we retain a minimal one-way "suppression" marker so the same person is not accidentally re-added — this marker cannot be reversed into personal information.

11Your rights

Under the APPs you can ask us to give you access to the personal information we hold about you and to correct it if it is inaccurate. To make a request about account data you hold with us directly, email privacy@faden.tech. We will respond within a reasonable time and may need to verify your identity first.

If you are a customer of a Studio, that Studio controls your information. Please direct access, correction and deletion requests to the Studio in the first instance; the Service gives every Studio the tools to fulfil them (data export, correction and erasure). We will support the Studio in responding.

Depending on where you live, you may have additional rights (for example, under the EU/UK GDPR or the laws of certain US states). We will honour valid requests to the extent those laws apply to our handling of your information.

12Cookies

We use a small number of strictly necessary cookies to keep you signed in, remember your preferences and protect the Service against abuse. We do not use third-party advertising cookies or sell data to advertisers. You can control cookies through your browser settings, though disabling essential cookies may stop you from signing in.

13Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal information from children. A Studio is responsible for the lawfulness of any customer information it enters, including obtaining any consent required for individuals under the age of majority.

14Changes to this Policy

We may update this Policy as the Service and our legal obligations evolve. When we make material changes we will update the effective date above and, where appropriate, notify Studios. Your continued use of the Service after a change takes effect means you accept the updated Policy.

15Complaints & contact

Our privacy contact is privacy@faden.tech. If you have a concern about how we handle personal information, contact us first — we take complaints seriously and will work with you to resolve them.

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Individuals overseas may also have the right to complain to their local data-protection authority.

For account-level privacy requests, email privacy@faden.tech. Questions? Email support@faden.tech.

This document is provided for transparency and is not legal advice. Your use of Faden is governed by the version in force at the time.